- Company Name
- DECIEM | THE ABNORMAL BEAUTY COMPANY
- Job Title
- Senior IT Compliance Analyst (17-month contract)
- Job Description
-
**Job Title**
Senior IT Compliance Analyst (17‑month contract)
**Role Summary**
Lead and manage technology compliance and cybersecurity initiatives for a fast‑growing consumer brand. Act as the primary subject‑matter expert on SOX, GxP, PCI‑DSS, and data privacy regulations, driving policy development, vendor risk assessment, incident remediation, and audit readiness. Collaborate cross‑functionally to embed secure controls, develop training and awareness programs, and report compliance metrics to senior leadership.
**Expactations**
- Deliver robust IT compliance framework on time and within scope.
- Maintain continuous compliance with SOX, PCI‑DSS, GxP, and data‑privacy laws.
- Effectively manage vendor risk assessments and incident remediation workstreams.
- Provide clear, actionable insights through dashboards and reporting.
- Foster a culture of security awareness across the organization.
**Key Responsibilities**
1. Assess, drive, track, and implement technology compliance policies, procedures, and controls.
2. Serve as SME on SOX, GxP, PCI‑DSS, and data‑privacy regulations for internal stakeholders.
3. Conduct vendor onboarding and risk assessments using questionnaires and tools.
4. Perform impact assessments and lead remediation for identified cyber‑security incidents.
5. Create, update, and enforce information, privacy, and data‑security policies and guidelines.
6. Coordinate internal self‑assurance audit readiness and engage external auditors.
7. Design and deliver cyber‑security best‑practice training and awareness campaigns.
8. Monitor emerging threats and recommend mitigation strategies.
9. Develop interactive dashboards (using Power BI, Tableau, etc.) to report compliance metrics to senior leadership.
10. Undertake ad‑hoc compliance tasks as assigned.
**Required Skills**
- 5+ years in cyber‑security and compliance with IT audit experience.
- Deep knowledge of SOX, PCI‑DSS, GxP, and data‑privacy regulations.
- Vendor risk assessment and incident/risk management experience.
- Strong analytical, problem‑solving, and project‑management skills.
- Excellent written and verbal communication; ability to train and influence across business units.
- Proficiency with compliance‑GRC tools and dashboard development (Power BI, Tableau, etc.).
- Collaborative mindset and proven cross‑functional stakeholder engagement.
**Required Education & Certifications**
- Bachelor’s degree in Information Technology, Computer Science, Information Security, or related field.
- Certified Information Systems Auditor (CISA) – required.
- CISSP, CISM, or equivalent – preferred.